File name:

ApnStub.bin.zip

Full analysis: https://app.any.run/tasks/a87b5aea-c37c-4b03-97ab-f6330f04d45a
Verdict: Malicious activity
Analysis date: June 01, 2020, 16:01:48
OS: Windows 7 Professional Service Pack 1 (build: 7601, 32 bit)
Indicators:
MIME: application/zip
File info: Zip archive data, at least v2.0 to extract
MD5:

1A1283DC768EAA1AF5CB47AE7AEA6450

SHA1:

562F192109CDCD091426DE63DC7B53AEEA7EDD2E

SHA256:

F6DCD47F70D1D528975D4C4155D20CFA24C8E8D8F193580E023E302FFE8B02A4

SSDEEP:

3072:6SgObbgG4tcbBRb32Juna3QwnO/T0gSE2xekLNpHu74/wfmaIQmBqiZ81TuZhf5Q:6lOVF9RTvyQd7VgxewNp+JuUJ681Toa

ANY.RUN is an interactive service which provides full access to the guest system. Information in this report could be distorted by user actions and is provided for user acknowledgement as it is. ANY.RUN does not guarantee maliciousness or safety of the content.
  • MALICIOUS

    • Application was dropped or rewritten from another process

      • ApnStub.exe (PID: 2100)
      • ApnStub.exe (PID: 3388)
      • ApnStub.exe (PID: 3728)
      • ApnStub.exe (PID: 3492)
      • ApnStub.exe (PID: 2512)
      • ApnStub.exe (PID: 2980)
  • SUSPICIOUS

    • Executable content was dropped or overwritten

      • WinRAR.exe (PID: 860)
    • Uses RUNDLL32.EXE to load library

      • WinRAR.exe (PID: 860)
  • INFO

    • Manual execution by user

      • ApnStub.exe (PID: 2100)
      • ApnStub.exe (PID: 3388)
      • cmd.exe (PID: 3660)
Find more information about signature artifacts and mapping to MITRE ATT&CK™ MATRIX at the full report
No Malware configuration.

TRiD

.zip | ZIP compressed archive (100)

EXIF

ZIP

ZipRequiredVersion: 788
ZipBitFlag: 0x0001
ZipCompression: Deflated
ZipModifyDate: 2020:06:01 18:01:11
ZipCRC: 0x3f99dfa1
ZipCompressedSize: 170131
ZipUncompressedSize: 356520
ZipFileName: ApnStub.bin
No data.
screenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshot
All screenshots are available in the full report
All screenshots are available in the full report
Total processes
44
Monitored processes
9
Malicious processes
1
Suspicious processes
0

Behavior graph

Click at the process to see the details
start winrar.exe rundll32.exe no specs apnstub.exe no specs apnstub.exe no specs cmd.exe no specs apnstub.exe no specs apnstub.exe no specs apnstub.exe no specs apnstub.exe no specs

Process information

PID
CMD
Path
Indicators
Parent process
860"C:\Program Files\WinRAR\WinRAR.exe" "C:\Users\admin\AppData\Local\Temp\ApnStub.bin.zip"C:\Program Files\WinRAR\WinRAR.exe
explorer.exe
User:
admin
Company:
Alexander Roshal
Integrity Level:
MEDIUM
Description:
WinRAR archiver
Exit code:
0
Version:
5.60.0
Modules
Images
c:\program files\winrar\winrar.exe
c:\systemroot\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\usp10.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\comdlg32.dll
1144"C:\Windows\system32\rundll32.exe" C:\Windows\system32\shell32.dll,OpenAs_RunDLL C:\Users\admin\AppData\Local\Temp\Rar$DIb860.15987\ApnStub.binC:\Windows\system32\rundll32.exeWinRAR.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
Windows host process (Rundll32)
Exit code:
0
Version:
6.1.7600.16385 (win7_rtm.090713-1255)
Modules
Images
c:\windows\system32\rundll32.exe
c:\systemroot\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\usp10.dll
c:\windows\system32\imagehlp.dll
2100"C:\Users\admin\Desktop\ApnStub.exe" C:\Users\admin\Desktop\ApnStub.exeexplorer.exe
User:
admin
Company:
Ask.com
Integrity Level:
MEDIUM
Description:
AskStub Application
Exit code:
4294967295
Version:
5.2.1.0
Modules
Images
c:\users\admin\desktop\apnstub.exe
c:\systemroot\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\urlmon.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\api-ms-win-downlevel-ole32-l1-1-0.dll
c:\windows\system32\ole32.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\user32.dll
2512C:\Users\admin\Desktop\ApnStub.exeC:\Users\admin\Desktop\ApnStub.execmd.exe
User:
admin
Company:
Ask.com
Integrity Level:
MEDIUM
Description:
AskStub Application
Exit code:
4294967295
Version:
5.2.1.0
Modules
Images
c:\users\admin\desktop\apnstub.exe
c:\systemroot\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\urlmon.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\api-ms-win-downlevel-ole32-l1-1-0.dll
c:\windows\system32\ole32.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\user32.dll
2980C:\Users\admin\Desktop\ApnStub.exeC:\Users\admin\Desktop\ApnStub.execmd.exe
User:
admin
Company:
Ask.com
Integrity Level:
MEDIUM
Description:
AskStub Application
Exit code:
4294967295
Version:
5.2.1.0
Modules
Images
c:\users\admin\desktop\apnstub.exe
c:\systemroot\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\urlmon.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\api-ms-win-downlevel-ole32-l1-1-0.dll
c:\windows\system32\ole32.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\user32.dll
3388"C:\Users\admin\Desktop\ApnStub.exe" C:\Users\admin\Desktop\ApnStub.exeexplorer.exe
User:
admin
Company:
Ask.com
Integrity Level:
MEDIUM
Description:
AskStub Application
Exit code:
4294967295
Version:
5.2.1.0
Modules
Images
c:\users\admin\desktop\apnstub.exe
c:\systemroot\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\urlmon.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\api-ms-win-downlevel-ole32-l1-1-0.dll
c:\windows\system32\ole32.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\user32.dll
3492C:\Users\admin\Desktop\ApnStub.exe /?C:\Users\admin\Desktop\ApnStub.execmd.exe
User:
admin
Company:
Ask.com
Integrity Level:
MEDIUM
Description:
AskStub Application
Exit code:
4294967295
Version:
5.2.1.0
Modules
Images
c:\users\admin\desktop\apnstub.exe
c:\systemroot\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\urlmon.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\api-ms-win-downlevel-ole32-l1-1-0.dll
c:\windows\system32\ole32.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\user32.dll
3660"C:\Windows\system32\cmd.exe" C:\Windows\system32\cmd.exeexplorer.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
Windows Command Processor
Exit code:
0
Version:
6.1.7601.17514 (win7sp1_rtm.101119-1850)
Modules
Images
c:\windows\system32\cmd.exe
c:\systemroot\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\winbrand.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\usp10.dll
3728C:\Users\admin\Desktop\ApnStub.exe /?C:\Users\admin\Desktop\ApnStub.execmd.exe
User:
admin
Company:
Ask.com
Integrity Level:
MEDIUM
Description:
AskStub Application
Exit code:
4294967295
Version:
5.2.1.0
Modules
Images
c:\users\admin\desktop\apnstub.exe
c:\systemroot\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\urlmon.dll
c:\windows\system32\api-ms-win-downlevel-ole32-l1-1-0.dll
c:\windows\system32\ole32.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\user32.dll
Total events
446
Read events
433
Write events
13
Delete events
0

Modification events

(PID) Process:(860) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\Interface\Themes
Operation:writeName:ShellExtBMP
Value:
(PID) Process:(860) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\Interface\Themes
Operation:writeName:ShellExtIcon
Value:
(PID) Process:(860) WinRAR.exeKey:HKEY_CLASSES_ROOT\Local Settings\MuiCache\12F\52C64B7E
Operation:writeName:LanguageList
Value:
en-US
(PID) Process:(860) WinRAR.exeKey:HKEY_CLASSES_ROOT\Local Settings\MuiCache\12F\52C64B7E
Operation:writeName:@C:\Windows\system32\NetworkExplorer.dll,-1
Value:
Network
(PID) Process:(860) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\ArcHistory
Operation:writeName:0
Value:
C:\Users\admin\AppData\Local\Temp\ApnStub.bin.zip
(PID) Process:(860) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\FileList\FileColumnWidths
Operation:writeName:name
Value:
120
(PID) Process:(860) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\FileList\FileColumnWidths
Operation:writeName:size
Value:
80
(PID) Process:(860) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\FileList\FileColumnWidths
Operation:writeName:type
Value:
120
(PID) Process:(860) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\FileList\FileColumnWidths
Operation:writeName:mtime
Value:
100
(PID) Process:(860) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\Interface
Operation:writeName:ShowPassword
Value:
0
Executable files
2
Suspicious files
0
Text files
2
Unknown types
0

Dropped files

PID
Process
Filename
Type
3728ApnStub.exeC:\Users\admin\AppData\Local\Temp\APN-Stub\Stb74698415-c915-4730-bb3a-8adebe7e8dec.logtext
MD5:
SHA256:
3492ApnStub.exeC:\Users\admin\AppData\Local\Temp\APN-Stub\Stb74698415-c915-4730-bb3a-8adebe7e8dec.logtext
MD5:
SHA256:
860WinRAR.exeC:\Users\admin\AppData\Local\Temp\Rar$DIb860.15987\ApnStub.binexecutable
MD5:817E86B7C18A015223A405E79DB836E9
SHA256:27699897A2773D58BA8840D0352C206F30D32CDB595155FF0A5411DA34C0C4C3
860WinRAR.exeC:\Users\admin\Desktop\ApnStub.binexecutable
MD5:817E86B7C18A015223A405E79DB836E9
SHA256:27699897A2773D58BA8840D0352C206F30D32CDB595155FF0A5411DA34C0C4C3
Download PCAP, analyze network streams, HTTP content and a lot more at the full report
HTTP(S) requests
0
TCP/UDP connections
0
DNS requests
0
Threats
0

HTTP requests

No HTTP requests
Download PCAP, analyze network streams, HTTP content and a lot more at the full report

Connections

No data

DNS requests

No data

Threats

No threats detected
No debug info